| Age | Commit message (Collapse) | Author |
|
Improve ippool documentation based on users feedback.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
We are living in 64-bit world long time, so there is very likely mempool
stats might overflow past 4GB and report incorrect values.
Updated mempool stats to use 64-bit counters so they don’t
wrap past 4 GB and print correctly in CLI.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
This is follow-up for https://github.com/accel-ppp/accel-ppp/pull/238
Adding missing documentation update.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
SSTP: load certificate chain instead of single one
|
|
Added an explicit break after handling TAG_VENDOR_SPECIFIC,
so vendor-specific PADR tags (e.g., TR-101) no longer fall
through and get misinterpreted as other tags like TAG_PPP_MAX_PAYLOAD.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
|
|
feat(build): Add MUSL detection and conditional linking
|
|
cmd: implement show ippool command
|
|
This commit introduces the ability to detect if the project is being
built with the MUSL C library.
A new variable `MUSL` is set to `ON` if MUSL is detected, and `OFF`
otherwise. This is achieved by checking the output of `ldd --version`.
The `accel-pppd/ctrl/pppoe/CMakeLists.txt` file is updated to
conditionally link the `connlimit` library only when building with MUSL.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
|
|
Command Usage:
accel-ppp# show ippool
IP Pool Usage Report
====================
<default>
total: 16384
used: 0
available: 16384
usage: 0%
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
Recently FreeRadius started to complain accel-ppp doesn't pass
BlastRADIUS check. This commit fixes that.
This commit implements protection against RADIUS blast attacks
by adding support for the Message-Authenticator attribute in
Access-Request packets. This security enhancement helps
prevent unauthorized access attempts and replay attacks
on RADIUS authentication.
- Added new configuration option `blast-protection=1`
in [radius] to enable Message-Authenticator inclusion
- Implemented HMAC-MD5 calculation for
Message-Authenticator attribute (RFC 2869)
- Modified packet building to include 18-byte Message-Authenticator
attribute when enabled
- Updated packet structure to support signing with shared secret
Enable blast protection by adding to the `[radius]` section:
```
blast-protection=1
```
When enabled, all Access-Request packets will include a
Message-Authenticator attribute with HMAC-MD5 signature,
providing cryptographic integrity verification and protection
against packet modification attacks.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
|
|
Allowed using multiple NTP servers in DHCP option 42
|
|
L2TP include calling number to calling station ID RA
|
|
|
|
|
|
I think the error handling code of `post_msg` is wrongly implemented due to coding typo. The `EPIPE` should be also considered and then return -1, just like `PPTP_write`:
https://github.com/xebd/accel-ppp/blob/1b8711cf75a7c278d99840112bc7a396398e0205/accel-pppd/ctrl/pptp/pptp.c#L539-L570
|
|
migrate from pcre to pcre2
|
|
build: fix build for entware (HAVE_GOOD_IFARP detection issue)
|
|
pppd_compat: add Framed-Interface-Id attribute support in radattr
|
|
build: fix compile errors on GCC 14
|
|
Fix issue #204
Proposed by https://github.com/achillelamb
|
|
fix(musl/l2tp_session_free): Fix, likely typo
|
|
It is logical, that function should remain same,
not changed to free.
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
This reverts commit 543700aed1ac045f12dfafd898bbbbae955fee31.
|
|
The radius library is now linked in pppoe if `-DRADIUS` is true; it wasn't any
issue when `-DRADIUS=FALSE`. This patch can't be worked around if the
user wants to use pppoe with chap-secrets, because radius conflicts with
chap-secrets.
|
|
Linux kernel before 4.11 has the issue decribed in the commit:
https://github.com/torvalds/linux/commit/2618be7dccf8739b89e1906b64bd8d551af351e6
It fails accel-ppp build on entware. Let's include sys/socket.h to avoid this issue.
All files that use linux/if_arp.h includes sys/socket.h before
|
|
PCRE is not supported anymore and removed from several distros
|
|
iputils: fix vlan creation on big-endian platforms
|
|
fix __WORDSIZE macro on musl 32 bit platforms
|
|
|
|
This patch fixes compile errors on GCC 14 like the following
/root/accel-ppp/accel-pppd/radius/packet.c: In function 'rad_packet_recv':
/root/accel-ppp/accel-pppd/radius/packet.c:142:72: error: passing argument 5 of 'recvfrom' from incompatible pointer type [-Wincompatible-pointer-types]
142 | n = recvfrom(fd, pack->buf, REQ_LENGTH_MAX, 0, addr, &addr_len);
| ^~~~
| |
| struct sockaddr_in *
In file included from /usr/include/netinet/in.h:10,
from /usr/include/arpa/inet.h:9,
from /root/accel-ppp/accel-pppd/radius/packet.c:10:
/usr/include/sys/socket.h:397:55: note: expected 'struct sockaddr * restrict' but argument is of type 'struct sockaddr_in *'
Reference: https://gcc.gnu.org/gcc-14/porting_to.html
|
|
|
|
This patch allows to build accel-ppp on mips32/ppc32 openwrt (musl)
|
|
Alpine Linux uses musl libc so now accel-ppp is tested under musl
Currently, Alpine Linux doesn't provide a link to the latest stable version
so direct link to Alpine 3.20 is used
Improved musl support might be used to run on platforms like openwrt
without additional patches
|
|
these test cases will help for pcre2 migration (issue #173)
|
|
Fixes the issue #124 "HTTP replay for non SSTP query" and log_debug2 in Triton lib
|
|
Fix issue https://github.com/accel-ppp/accel-ppp/issues/131
Proposed by https://github.com/kugel-
Author: Thomas Martitz <kugel@rockbox.org>
Signed-off-by: Denys Fedoryshchenko <denys.f@collabora.com>
|
|
|
|
|
|
This reverts commit 635ab1b77b06a8891479a46a0e1ba88315ff3958.
|
|
2. Fixes log_debug2 in Triton lib
|
|
bad commit: bc85fe18e6066814d95d1bdc1a3dfe8cc8f9786f
Reported-By: StasN77 <stasn77@gmail.com>
Signed-off-by: Sergey V. Lobanov <sergey@lobanov.in>
|
|
Signed-off-by: Sergey V. Lobanov <sergey@lobanov.in>
|
|
|
|
related net-snmp change: https://github.com/net-snmp/net-snmp/commit/a2cb167514ac0c7e1b04e8f151e0b015501362e0
Signed-off-by: Sergey V. Lobanov <sergey@lobanov.in>
|
|
clsact + fwmark
|
|
|